CVE-2026-100609 Overview
CVE-2026-100609 is an Insecure Direct Object Reference (IDOR) vulnerability in Flowise, affecting the flowise and flowise-components npm packages through version 3.1.4. The application looks up credentials by ID using findOneBy({ id: credentialId }) without filtering on the requesting user's workspace. An authenticated user in one workspace can supply a credential UUID belonging to another workspace. The server then decrypts and uses the victim workspace's OpenAI or ElevenLabs API key on the attacker's behalf. The flaw maps to [CWE-639: Authorization Bypass Through User-Controlled Key]. No patched version was available at the time of publication.
Critical Impact
Authenticated cross-workspace API key abuse enables attackers to consume and effectively exfiltrate third-party AI service credentials belonging to other tenants.
Affected Products
- Flowise npm package flowise through 3.1.4
- Flowise npm package flowise-components through 3.1.4
- Deployments integrating OpenAI Assistants, ElevenLabs text-to-speech, and the export-import feature
Discovery Timeline
- 2026-09-26 - CVE-2026-100609 published to NVD
- 2026-09-30 - Last updated in NVD database
Technical Details for CVE-2026-100609
Vulnerability Analysis
Flowise exposes several API endpoints that resolve credentials by their UUID without validating workspace ownership. Affected code paths include getAllOpenaiAssistants and getSingleOpenaiAssistant reachable through GET /api/v1/openai-assistants and GET /api/v1/openai-assistants/:id. The uploadFilesToAssistant handler at POST /api/v1/openai-assistants-file/upload/ is also affected. The deleteAssistant handler at DELETE /api/v1/assistants/:id becomes exploitable after importing a poisoned assistant row via POST /api/v1/export-import/import. The shared helper used by getVoices at GET /api/v1/text-to-speech/voices carries the same flaw.
Root Cause
The server performs credential lookups with findOneBy({ id: credentialId }) and omits a workspaceId condition. Authorization is implicitly tied to authentication rather than tenancy, so any authenticated user who knows or guesses a credential UUID can reference it. Flowise decrypts the stored secret and uses it in outbound requests to OpenAI or ElevenLabs on the caller's behalf.
Attack Vector
An attacker authenticates to any workspace on a shared Flowise instance. They then issue an API call to one of the affected endpoints, substituting a credentialId belonging to another workspace. Flowise retrieves and decrypts the target credential, invoking the upstream AI provider with the victim's API key. The attacker can enumerate assistants, upload files, trigger text-to-speech calls, or delete imported assistants, all billed and attributed to the victim tenant.
No verified exploitation code is published. See the GitHub Security Advisory GHSA-27w2-26m5-x82c and the VulnCheck Advisory on Flowise for technical details.
Detection Methods for CVE-2026-100609
Indicators of Compromise
- Requests to /api/v1/openai-assistants, /api/v1/openai-assistants/:id, /api/v1/openai-assistants-file/upload/, /api/v1/assistants/:id, or /api/v1/text-to-speech/voices where the credentialId parameter does not belong to the caller's workspace.
- Unexpected POST /api/v1/export-import/import activity followed shortly by DELETE /api/v1/assistants/:id calls.
- Spikes in OpenAI or ElevenLabs API usage, billing anomalies, or rate-limit errors inconsistent with normal workspace workloads.
Detection Strategies
- Correlate the authenticated user's workspaceId with the workspaceId of the credential record referenced in each request and alert on mismatches.
- Audit application logs for credential lookups that bypass tenant scoping, especially within handlers that call findOneBy({ id: credentialId }).
- Baseline per-workspace outbound traffic to api.openai.com and api.elevenlabs.io and alert on deviations.
Monitoring Recommendations
- Forward Flowise application and reverse-proxy logs to a centralized analytics pipeline for cross-tenant query analysis.
- Enable upstream provider audit logs (OpenAI usage dashboards, ElevenLabs history) and reconcile them against expected workspace activity.
- Monitor for export-import operations that introduce assistant rows referencing credential IDs from other workspaces.
How to Mitigate CVE-2026-100609
Immediate Actions Required
- Restrict Flowise access to trusted users only and disable self-service registration on multi-tenant deployments.
- Rotate all OpenAI and ElevenLabs API keys stored in Flowise and reduce their scope or spending limits where supported.
- Disable or gate the export-import endpoint (POST /api/v1/export-import/import) behind administrative review.
Patch Information
No patched version of flowise or flowise-components was available at the time of publication. Track the GitHub Security Advisory GHSA-27w2-26m5-x82c for updates and apply fixed versions once released.
Workarounds
- Deploy a reverse-proxy or WAF rule that inspects requests to affected endpoints and blocks credentialId values not owned by the authenticated workspace.
- Segregate tenants by running separate Flowise instances per workspace with isolated credential stores until an upstream fix is published.
- Revoke unused credentials and prefer short-lived, workspace-scoped API keys with strict upstream quota caps.
Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.